Ethical Hacking News
In a recent incident, Switzerland's Federal Office for Information Technology and Communications (FOITT) suffered a cyberattack that exposed approximately 200 accounts on its on-premises SharePoint servers. The attack is attributed to previously unknown actors who exploited vulnerabilities in Microsoft's SharePoint software. Experts have warned that SharePoint is increasingly targeted by cybercriminals and nation-state actors due to its deep integration with Microsoft authentication, making it essential for organizations to prioritize cybersecurity and implement robust security protocols.
Switzerland's Federal Office for Information Technology and Communications (FOITT) suffered a cyberattack that exposed 200 accounts on its SharePoint servers.The attack is attributed to previously unknown actors who exploited vulnerabilities in Microsoft's SharePoint software, specifically CVE-2026-50522 and CVE-2026-58048.Experts warn that SharePoint is increasingly targeted by cybercriminals and nation-state actors due to its deep integration with Microsoft authentication.The incident highlights the importance of timely patching and rotating machine keys to prevent long-term access for attackers.CERT-EU recommends updating affected servers as soon as possible, rotating credentials, and conducting a compromise assessment to identify potentially affected SharePoint instances.Organizations are advised to reconsider exposing Microsoft SharePoint Server directly to the internet due to recent critical vulnerabilities.
In a recent incident, Switzerland's Federal Office for Information Technology and Communications (FOITT) suffered a cyberattack that exposed approximately 200 accounts on its on-premises SharePoint servers. The attack is attributed to previously unknown actors who exploited vulnerabilities in Microsoft's SharePoint software.
The incident occurred when the attackers used the recently disclosed vulnerabilities in mid-July, which were later tracked as CVE-2026-50522 and CVE-2026-58048. The first vulnerability, tracked as CVE-2026-50522, has a CVSS score of 9.8, allowing an attacker to execute remote code over a network with low complexity. The second vulnerability, tracked as CVE-2026-58048, enables full database administrator access.
The attackers' tactics, economics, and procedures (TEPs) are not yet clear, but experts have warned that SharePoint is increasingly targeted by cybercriminals and nation-state actors due to its deep integration with Microsoft authentication. Attackers exploiting vulnerabilities could use it as an entry point to compromise wider networks, making direct internet exposure of SharePoint servers a growing security risk.
The FOITT immediately reset the affected passwords, blocked external internet access to SharePoint, and began patching. However, the incident highlights the importance of timely patching and rotating machine keys to prevent long-term access for attackers. The Swiss agency has shared all relevant technical indicators with critical infrastructure operators through the national cybersecurity agency's platform.
The breach is believed to have occurred due to external attacks on SharePoint servers, which were exposed to the internet. However, some experts have pointed out that the vulnerability could be used by an attacker to maintain long-term access. The incident serves as a reminder for organizations still running on-premises SharePoint exposed to the internet to apply the July patches and rotate machine keys.
In response to this incident, CERT-EU strongly recommends updating affected servers as soon as possible, rotating credentials for any assets that may have been vulnerable and exposed to the internet, and conducting a compromise assessment to identify potentially affected SharePoint instances. The organization's advisory warns that given the number of recent critical vulnerabilities affecting SharePoint, organizations should reconsider exposing any Microsoft SharePoint Server directly to the internet.
The FOITT is reinstalling the affected servers as a precaution after the cyber incident. External internet access remains blocked until the work is complete, while federal employees can still access and share documents through alternative channels. The incident underscores the importance of cybersecurity awareness and proactive measures to prevent such incidents.
The recent breach has sparked concerns about the security of SharePoint and its potential vulnerabilities. This incident highlights the need for organizations to prioritize cybersecurity and implement robust security protocols to protect their systems from external threats. By understanding the risks and taking proactive steps, organizations can minimize the impact of such incidents and ensure the integrity of their data.
Related Information:
https://www.ethicalhackingnews.com/articles/Unveiling-the-Vulnerability-A-Closer-Look-at-SharePoints-Security-Flaws-ehn.shtml
https://securityaffairs.com/196625/hacking/sharepoint-flaws-used-to-hack-switzerlands-federal-it-agency.html
https://www.swissinfo.ch/eng/various/cyberattack-on-the-federal-office-for-information-technologys-sharepoint-server/91843136
https://nvd.nist.gov/vuln/detail/CVE-2026-50522
https://www.cvedetails.com/cve/CVE-2026-50522/
https://nvd.nist.gov/vuln/detail/CVE-2026-58048
https://www.cvedetails.com/cve/CVE-2026-58048/
Published: Tue Aug 4 16:35:18 2026 by llama3.2 3B Q4_K_M